Getting Data In

Splunk onboarding field values mistake

splunklearner
Communicator

We are trying to onboard data from F5 WAF devices to our splunk. F5 team sending it by key value pairs. And one of them is "headers:xxxxxxxxx" (nearly 40 words). When data is getting  onboarded and we are checking in splunk web, below the table format headers field is not capturing correctly. It is giving some other value. Same with other field where its value is getting truncated. Please help me in this case.

Labels (1)
0 Karma

dural_yyz
Motivator

https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Propsconf#Structured_Data_Header_Extraction...

 

Start here and see what you can find, otherwise please provide your props.conf configuration if possible so we can actually see what is being attempted vs an example of the actual output.  A sample of the log helps when deciphering how your existing props.conf is interacting with the data.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...